首页    期刊浏览 2024年11月15日 星期五
登录注册

文章基本信息

  • 标题:DoS Forensic Exemplar Comparison to a Known Sample
  • 本地全文:下载
  • 作者:Professor Paul Knight ; Dr. Narasimha Karpoor Shashidhar
  • 期刊名称:International Journal of Computer Science and Security (IJCSS)
  • 电子版ISSN:1985-1553
  • 出版年度:2018
  • 卷号:12
  • 期号:1
  • 页码:11-21
  • 出版社:Computer Science Journals
  • 摘要:The investigation of any event or incident often involves the evaluation of physical evidence. Occasionally, a comparison is conducted between an evidentiary sample of unknown origin and that of an appropriate known sample. In a Denial of Service (DoS) attack, items of evidentiary value may cross the spectrum from anecdotes to useful information in firewall logs or complete packet captures. Because of the spoofed or reflective nature of DoS attacks, relevant information leading to the direct identification of the perpetrator is rarely available. In many instances, this underscores the significance of the investigator's ability to accurately identify the tool utilized by the suspect. For a DoS attack scenario, this would likely involve a commercially available stresser or criminal bot infrastructure. In this paper, we propose the concept of a DoS exemplar and determine if the comparison of evidentiary samples to an appropriate known sample of DoS attributes could add value in the investigative process. We also provide a simple tool to compare two DoS flows.
  • 关键词:Denial of Service Flow Comparison; DoS Similarity Score; DoS Exemplar; Stresser.
国家哲学社会科学文献中心版权所有